Telecom Identity Bridging for Web Application Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face difficulties in managing multiple usernames and passwords across disjointed application domains, leading to a cumbersome authentication and authorization process, which discourages users from engaging with telecom-hosted applications as they prefer over-the-top (OTT) services for single-sign-on experiences.

Innovation Solution

A method and system that issue access tokens associated with user identifiers subscribed to telecommunications networks, allowing web-based applications to authenticate and authorize user data access, leveraging OTT proxy elements to bridge user authentication and authorization across internet and telecom domains, utilizing mechanisms like OAuth 2.0 for token-based authorization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users manage multiple usernames and passwords across different application domains, then security and access control are maintained, but user convenience and ease of operation deteriorate

Engineering Contradiction:
Improvesecurity and access controlVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary authentication system that mediates between users and multiple applications. This intermediary manages credentials centrally and provides delegated authorization, allowing users to authenticate once and access multiple applications without manually managing separate usernames and passwords for each application domain.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a universal authentication mechanism that works across multiple application domains (telecom, enterprise, and Internet domains). This single authentication system provides multi-functional access control, enabling users to authenticate once and gain access to various applications through delegated authorization tokens.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If users log in multiple times each day to different applications, then access control is maintained, but time consumption and productivity worsen

Engineering Contradiction:
Improveaccess controlVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary authentication where users authenticate once in advance to an intermediary system. The system then pre-issues delegated authorization tokens that allow users to access multiple applications without repeating the authentication process, significantly reducing time consumption while maintaining access control.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables continuous access to multiple applications through delegated authorization tokens that remain valid across different application domains. This eliminates the need for repeated login actions, allowing users to continuously access services without interruption or time loss.

Inventive Principle:
Principle #20Continuity of useful action

3Adaptability or versatility

If users enter and manage personal information across all application domains, then data access is enabled, but complexity of information management increases

Engineering Contradiction:
Improvedata accessVSAvoidinformation management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts personal information management from individual application domains and centralizes it in an intermediary authentication system. Users enter their personal information once with the intermediary, which then manages and secures this data, extracting the burden of information management from users while enabling versatile data access across applications through controlled token issuance.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8667579B2Methods, systems, and computer readable media for bridging user authentication, authorization, and access between web-based and telecom domains
Publication Date: 2014.03.04 RIBBON COMMUNICATIONS OPERATING CO INC
  • US8667579B2 patent drawing
  • US8667579B2 patent drawing
  • US8667579B2 patent drawing

AI summary

Methods, systems, and computer readable media for bridging user authentication, authorization, and access between web-based and telecom domains are disclosed. In one example, a method includes issuing, to an application hosted in a web-based network, an access token associated with a user identifier subscribed to a telecommunications network, wherein the access token is issued in response to receiving telecommunications network credentials from a client device associated with the user identifier and receiving, at an over the top (OTT) proxy element in the telecommunications network from the application, the access token for requesting user data associated with the client device to be used to access the application. The method further includes retrieving the user data if the access token is valid a telecommunications network context condition is met and providing the user data to the application, wherein access to the application by the client device is based on the user data.